Help

Common questions about using Slivr.

Getting started

What is Splintr?

Splintr is a federated social network that anyone can host on their own server. You own your data, control who sees it, and can connect with people on other Splintr servers without giving up that control.

How do I create an account?

If this server allows registration, click Sign Up in the navigation bar. You will need a username, email address, and password. Some servers require an invitation from an existing member.

What are nodes and clusters?

In Splintr, your account is called a node — it is your identity on the network. A server that hosts multiple user accounts is called a cluster. A server can also be set up as a single node, where one person owns the entire site. Either way, your node can connect with nodes on other servers through federation.

Posts and content

How do I write a post?

From your feed, type in the editor at the top and press Post. Posts support Markdown formatting: **bold**, *italic*, # Heading, and links with [text](url).

Can I add images to posts?

Yes. Use the media uploader in the post editor to attach images. Uploaded media is stored on your server and served through signed URLs for privacy.

Who can see my posts?

You choose per-post or set a default in your privacy settings. Options include public, friends only, specific friend groups, selected users, and private. Friend groups let you share with a curated list — for example, a "Close Friends" group — without making content visible to your entire friend list.

Friends and federation

How do I add a friend on another server?

Visit their profile on their server. If you are logged in to your home server, you can send a friend request through the federation handshake — your servers will securely verify each other's identity and establish the connection between your nodes.

See the About page for more on how federation works.

What happens if a friend's server goes offline?

You will not be able to see new posts from nodes on that server until it comes back. Your local data — your own posts, your friend list — is unaffected. Federation is designed to degrade gracefully when remote servers are unavailable.

Privacy and security

Is my data encrypted?

Yes, at multiple levels. All connections between servers use HTTPS (TLS). Sensitive profile data like email addresses are encrypted at rest in the database, and your password is hashed with bcrypt.

Every post is cryptographically signed with your personal Ed25519 key, which lets anyone verify that you are the real author and that the content has not been tampered with — especially useful for posts shared across federated servers.

Private messages use end-to-end hybrid encryption: each message is encrypted with a random session key, and that session key is then encrypted separately for each recipient using their public key.

How do I adjust my privacy settings?

Once logged in, open Privacy from the sidebar menu. You can control who sees your profile, posts, friends list, and bookmarks. Settings apply to both local and federated visitors.

Security layers in detail

Splintr uses multiple layers of security to protect your account and data. Click any card to see how it works.

🛡️
Network and transport
TLS, CORS, rate limits, cookies
▾

TLS enforcement — cookies are HTTPS-only when TLS is available. Federation SSL verification enforced in production.

CORS — dynamic single-origin echo against known peers. Unknown origins get no headers. Wildcard never used.

Rate limiting — 100 requests/hour per remote server, 5 login attempts per 15 minutes. All requests logged.

Cookies — HttpOnly, SameSite=Lax, browser-session lifetime. No persistent cookies.

🔑
Authentication
CSRF, sessions, tokens, JWT
▾

CSRF tokens — per-session, timing-safe comparison, origin header cross-check on every API call.

Session fixation — session ID regenerated on every login, old session destroyed.

Federation tokens — single-use, server-scoped, expiring. Consumed immediately on verification.

Federation JWTs — RS256, 15-minute lifetime, audience-scoped to prevent replay across servers.

👥
Authorization and privacy
ACLs, friendships, blocks, delegation
▾

Privacy levels — Public through Private, per-post. Feed queries filter every post by your relationship to its author.

Friendship checks — local and federated. Friend-of-friend access uses a cross-server privacy mesh.

Block propagation — blocks sync across the federation so they're respected network-wide.

Delegation — shared accounts with owner/admin/contributor roles and optional post approval.

📝
Content integrity
Signatures, XSS, sandboxing
▾

Post signing — Ed25519 signature on every post. Verified on read. Revoked keys show "unsigned," not "tampered."

XSS prevention — escape-first rendering pipeline. All user input goes through htmlspecialchars before markdown processing.

Plugin sandboxing — strict iframe sandbox, postMessage bridge, manifest permission allowlist, server-side enforcement, storage quotas.

Federation envelopes — RSA-2048 signed, 5-minute timestamp window, DNS identity verification.

🔒
Encryption
AES-256, Ed25519, Argon2id, PFS
▾

Profile fields — AES-256-CBC for email, name, phone. No plaintext email column in the database.

Messages — per-conversation AES-256-GCM session keys, encrypted per-recipient with their public key.

Key wrapping — private keys wrapped with Argon2id-derived key from your password. Never stored in plaintext.

Perfect forward secrecy — ephemeral X25519 key exchange for server-to-server data. Past exchanges stay safe if a key is compromised.

Memory safety — sodium_memzero wipes keys from RAM immediately after use.

📋
Audit and logging
Security log, admin trail, federation log
▾

Security events — auth failures, CSRF violations, and gateway denials logged with identity and IP.

Admin audit trail — every admin action logged with who, what, when, and target.

Federation tracking — every inbound request logged by remote node and type.

API usage — all gateway requests logged with action, timing, success/failure, and client IP.